The OpenNMS Group
First CVE: Feb 22, 2023Active for: 3 years
16
CVEs Published
More CVEs Published than 36% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by The OpenNMS Group as a CNA, 87.5% affect products that The OpenNMS Group develops as a vendor.
87.5%
12.5%
Self-reported: 14Third-party: 2
Of all the CVEs published that affect products developed by The OpenNMS Group, 46.7% are self-published by The OpenNMS Group as a CNA.
46.7%
53.3%
Self-published: 14Published by other CNAs: 16
Trends Over Time
The number and severity of CVEs published by The OpenNMS Group over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2023
3 years ago
Most Recent CVE
Jun 26, 2025
393 days ago
Top CVEs
All CVEs published by The OpenNMS Group as a CNA, regardless of affected vendor or product.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0872HIGH The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solutio | Aug 14, 2023 | 8.0 | 37 | NO | YES |
CVE-2023-40315HIGH In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ | Aug 17, 2023 | 8.0 | 33 | NO | YES |
CVE-2023-40313HIGH A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code exe | Aug 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-40612HIGH In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection at | Aug 23, 2023 | 8.0 | 21 | NO | NO |
CVE-2023-0871MEDIUM XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which ca | Aug 11, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-0870MEDIUM A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidentia | Mar 22, 2023 | 6.7 | 21 | NO | NO |
CVE-2023-0868MEDIUM Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users
should upgrade t | Feb 23, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-0846MEDIUM Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confident | Feb 22, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-53121MEDIUM Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow an attacke | Jun 26, 2025 | 6.9 | 20 | NO | NO |
CVE-2023-0867MEDIUM Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confid | Feb 23, 2023 | 6.1 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA16 CVEs
75%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (37.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network8 (50.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required8 (50.0%)
Privileges Required
Low8 (50.0%)
High0 (0.0%)
None8 (50.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
12.5% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by The OpenNMS Group as a CNA.
Media Mentions
Media articles that mention a CVE ID published by The OpenNMS Group as a CNA — matched by CVE ID, not by organization name.